Article 21
Right to Object
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
Enable individuals to object to certain public-interest, legitimate-interest, and direct-marketing processing, and stop processing when the applicable legal test requires it.
Points of focus
- Offer clear objection channels, especially for direct marketing
- Stop direct marketing and related profiling after objection
- Assess compelling grounds for other challenged processing
Implementation notes
Represent objections as durable purpose-specific suppression signals, distribute them to campaign and audience tools, and retain the minimum suppression record needed to prevent re-enrollment. Operationalize offer clear objection channels, especially for direct marketing in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain suppression-list configuration and marketing tests with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a user unsubscribes from email but remains in audience-sync advertising Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample suppression-list configuration and marketing tests with dates and named reviewers. Be ready to walk through how you detect and correct: a user unsubscribes from email but remains in audience-sync advertising
Evidence auditors typically request:
- Suppression-list configuration and marketing tests
- Objection case records and balancing decisions
- Propagation evidence across advertising and CRM vendors
Common gaps
- A user unsubscribes from email but remains in audience-sync advertising
- Suppression data is deleted during account erasure and the person is later re-imported
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 21 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 21: Regulation (EU) 2016/679, Article 21 — Right to Object